Job Title
Senior IT Security Analyst (Cybersecurity Governance, Risk & Compliance - GRC)
Work Schedule / Location
- Location: Columbus, Ohio
- Work Schedule: Onsite 5 days per week
- Duration: 08/31/2026 06/30/2027
- Candidates must be able to work onsite at the client location in Columbus, Ohio.
Interview Process
- Interview format to be confirmed (Microsoft Teams or Onsite).
- Technical interview focused on cybersecurity, governance, risk management, compliance, cloud security, and security operations.
Job Description
We are seeking an experienced Senior IT Security Analyst to support enterprise cybersecurity, governance, risk management, compliance (GRC), and security operations initiatives. This role is responsible for evaluating security risks, supporting regulatory compliance, conducting security assessments, coordinating audit activities, and assisting with the implementation and maintenance of security controls across enterprise applications, infrastructure, cloud environments, and third-party services.
The ideal candidate will work closely with security leadership, infrastructure teams, application teams, project managers, business stakeholders, and external vendors to strengthen the organization's cybersecurity posture while ensuring compliance with federal, state, and industry security standards.
Key Responsibilities
- Support enterprise cybersecurity, governance, risk management, compliance, and security operations initiatives.
- Perform security risk assessments and technical security reviews for applications, infrastructure, cloud services, and technology initiatives.
- Conduct vendor security assessments and evaluate SOC reports, security questionnaires, architecture diagrams, and compliance documentation.
- Support compliance efforts related to NIST, CMS, HIPAA, ARC-AMP-E/MARS-E, IRS Publication 1075, and other applicable security frameworks.
- Participate in audit preparation, evidence collection, remediation tracking, corrective action planning, and audit response activities.
- Identify cybersecurity risks and collaborate with technical and business teams to implement mitigation strategies.
- Support Governance, Risk, and Compliance (GRC) programs, including policies, standards, procedures, and documentation.
- Participate in vulnerability management, continuous monitoring, incident response coordination, and operational security initiatives.
- Review cloud environments, enterprise architecture, infrastructure changes, and third-party integrations for security compliance.
- Track security findings, vulnerabilities, POA&Ms, and remediation activities.
- Assist with implementation and maintenance of NIST-aligned security controls.
- Prepare executive security reports, compliance documentation, risk assessments, and security metrics.
- Participate in Secure Software Development Lifecycle (SDLC) activities to ensure security is integrated throughout project implementation.
- Provide security guidance for enterprise applications, cloud technologies, and third-party solutions.
- Develop and maintain security documentation, standards, procedures, and compliance artifacts.
- Communicate security risks and recommendations to both technical and non-technical stakeholders.
Required Qualifications
- Bachelor's degree in Cybersecurity, Information Security, Computer Science, Information Systems, or a related field.
- Minimum 5 years of professional experience in cybersecurity, information security, governance, risk management, or compliance.
- Minimum 3 years of experience conducting security risk assessments, vendor security reviews, or compliance evaluations.
- Experience supporting security frameworks such as NIST, CMS, HIPAA, ARC-AMP-E/MARS-E, IRS Publication 1075, or comparable standards.
- Experience supporting Governance, Risk, and Compliance (GRC) programs.
- Experience with vulnerability management, audit readiness, evidence collection, remediation tracking, and continuous monitoring.
- Experience reviewing cloud technologies, enterprise architecture, infrastructure, and third-party integrations.
- Strong understanding of cybersecurity governance, compliance, security controls, and risk management.
- Excellent analytical, documentation, communication, organizational, and problem-solving skills.
- Ability to work independently while collaborating effectively with cross-functional teams.
Preferred Qualifications
- CISSP, CISM, CISA, Security+, CGRC, or equivalent cybersecurity certification.
- Experience securing Azure, AWS, or Google Cloud environments.
- Experience with SIEM technologies and enterprise security monitoring.
- Experience performing vendor security assessments and third-party risk management.
- Knowledge of Medicaid systems or state government security practices.
- Experience working in Agile project environments.
- Strong leadership and stakeholder management skills.